The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the Whatsapp listing page.
Hosted MCP gateway in front of the wacli WhatsApp CLI.
The idea: someone links their WhatsApp account once (QR, like WhatsApp Web) and gets a URL plus a bearer token. Any MCP client can then read, search — and optionally send — without running anything locally.
Status: public alpha. Single host, single process. Live at https://wacli.me.
MIT licensed. Self-hosting is a first-class path — see "Running" below.
| Path | Purpose |
|---|---|
/ | landing page |
/mcp | MCP over Streamable HTTP, Authorization: Bearer … |
/healthz | liveness + tenant count |
/connect | self-service linking: live QR, issues a token |
/.well-known/oauth-* | OAuth 2.1 discovery — clients fetch their own credentials |
config/tenants.json:
The file is re-read every 5 seconds — adding a tenant needs no restart. A token maps to exactly one
store directory; tools are constructed per request against that store, so two tenants cannot see each
other's data. allowSend is what registers the send_message tool at all; leave it false unless
the account owner explicitly asked for write access.
Generate a token with openssl rand -hex 32.
Environment:
| Variable | Default | Meaning |
|---|---|---|
PORT | 8787 | listen port |
HOST | 127.0.0.1 | bind address — keep loopback, expose via tunnel |
WACLI_BIN | ./bin/wacli | wacli binary |
WACLI_ME_TENANTS | ./config/tenants.json | tenant file |
Without a sync daemon the store only holds what was fetched during the last run.
--read-only, so a compromised tool call cannot mutate the store.MIT, see LICENSE. site/assets/qrcode.min.js is Kazuhiko Arase's
qrcode-generator, vendored unchanged (MIT). wacli itself is a separate MIT project — this repository only drives it.
Linking an account uses an unofficial WhatsApp client. That is against WhatsApp's terms of service, and Meta may block a number for it. Run it on accounts you own, and tell your users the same.